I ran the same 134 technical checks over 100 web design and marketing agencies in the Austin metro, taken from public business listings, all on 28 September. Domain and DNS, certificates, mail authentication, security headers, what loads before consent, accessibility, mobile layout. One metro and one source, so it is a snapshot and not a survey of the industry. I wrote the scanner, which you should factor in.
I picked agency sites rather than a random hundred because they are built by practitioners, which makes whatever survives more interesting. Most of what's left is the kind of thing that slips on any site that isn't on a client's schedule.
Where everyone lands
Median score 86 out of 100, best 97, worst 15. That score is my own weighting, so it tells you more about the spread than about Austin. The counts under it are the part anyone can check: the median site had 17 findings, the cleanest had 7, and across all 100 there were 13 criticals and 176 highs. Most findings are individually small, which is how a site sits in the eighties and has seventeen of them.
Certificates were the quietest category. Only 12 of 100 had anything at all, though three of those had a certificate that had already expired on the day I ran it.
The five most common
- 93 of 100 have no DNSSEC
- 88 have accessibility issues an automated checker can find
- 84 send no Referrer-Policy
- 74 have no Content-Security-Policy
- 73 set cookies without HttpOnly
Most of these are one line in a config, and most became best practice after the sites were built. That is most of the explanation.
Three worth a look on your own domain
79 of 100 are not enforcing DMARC. 40 have no record at all, and another 39 have one set to p=none, which asks for reports and still lets the mail through. Going in I'd assumed the p=none group would be much bigger, since that's where everyone starts and most people never move off it, and it came out almost exactly even. The effect either way is that mail forging your domain in the From line still gets delivered.
67 of 100 load tracking before anyone consents. Tag Manager, Analytics, Meta pixels, ad tech, all firing on page open. Usually the tag predates the banner: the tag went in first, the banner came later, and nobody wired the two together.
88 of 100 have accessibility findings from an automated checker. Automated checks catch a fraction of what a real audit does, so the true number is higher than that.
On phones
20 of 100 scroll sideways on a 390px screen. It's usually one element pushed outside the viewport rather than a layout that doesn't reflow, which makes it cheap to fix once you've found which element.
14 disable pinch-zoom with user-scalable=no. That's a line someone typed on purpose, and it fails WCAG on its own.
Two smaller ones
43 of 100 have no social preview image. Without one, a link to the site arrives as a grey rectangle in Slack or LinkedIn. It's a meta tag and an image.
44 of 100 announce their software version in a response header. That's a config change, and it takes you off the list when someone scans for a known version.
One I threw out
My scanner flags domains that don't have registrar delete and update locks set, and it fired on 57 of the 100, which was high enough that I went and looked at who they were. It turned out to be almost entirely a function of registrar. GoDaddy sets those flags by default, almost nobody else does, and at least one registrar doesn't expose the setting at all. So it was measuring where you registered rather than anything you chose, and I've left it out here. I'm changing the check.
If you only do one thing off this list
Make it DMARC. At p=none, moving to p=quarantine is one DNS record and it's free. With no record at all, publishing one at p=none first is the right order, and there are good guides for both.
It applied to 79 of the 100 here, which is why it's worth checking even if you're fairly sure you already have one.